Try our new research platform with insights from 80,000+ expert users

LogRhythm SIEM vs Sumo Logic Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
LogRhythm SIEM enhances detection, response times, productivity, and security posture, offering cost-effectiveness and resource savings for medium-sized organizations.
Sentiment score
6.1
Sumo Logic Security reduces downtime and improves processes, saving time and proving cost-effective compared to alternatives.
 

Customer Service

Sentiment score
5.4
LogRhythm SIEM's support excels in expertise and quick resolutions, earning high satisfaction despite occasional delays.
Sentiment score
6.9
Sumo Logic Security's customer service is responsive and proactive, with effective support, though minor communication improvements are suggested.
The technical support is good; we have a separate portal for partners, and since we are paying for the service, they provide a response timeframe based on severity—critical issues are addressed within four hours, medium issues within one day, and non-urgent issues may take a couple of days.
Cyber Security Engineer at Diyar United Company
Customer support is very helpful and effectively solves my problems.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
They have a response time of forty-eight hours, which is not instant support.
SOC Analyst at a computer software company with 1,001-5,000 employees
In general, they usually provide continuous support post-implementation, being in touch and trying to help, which makes their after-sale process better than Splunk.
CSO at Altera
 

Scalability Issues

Sentiment score
7.8
LogRhythm SIEM is highly scalable, easily expands across environments, and integrates well, suitable for medium to large enterprises.
Sentiment score
7.6
Sumo Logic Security efficiently scales for large data and users, highly rated for adaptability despite potential increasing costs.
LogRhythm SIEM is highly scalable as it has modular components allowing me to expand storage, indexing, or other resources as needed.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
LogRhythm SIEM is scalable; it can handle about 200 or 500 devices without much difference.
Cyber Security Engineer at Diyar United Company
The scalability of LogRhythm SIEM is good enough, warranting an eight out of ten rating.
Security Engineer at Granicus Inc.
The tool has high scalability because everything is based in the cloud.
Deputy Country Manager at PT Securite Asia Indonesia (ABP Securite)
I did not face any significant issues with Sumo Logic Security, but the pricing may be a concern as they try to upsell and raise the prices very quickly.
CSO at Altera
 

Stability Issues

Sentiment score
4.7
LogRhythm SIEM is stable with high uptime, strong support, handling large data, though updates may affect stability.
Sentiment score
8.0
Sumo Logic Security is stable and reliable, with minimal disruptions, rare latency issues, and highly rated performance by users.
The platform needs regular updates to fix problems encountered with each quarterly patch and version release.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
LogRhythm SIEM still needs improvement regarding stability, particularly in environments with heavy data consumption.
Security Engineer at Granicus Inc.
If there are many records, the system may stop or the UI may become unresponsive.
SOC Analyst at a computer software company with 1,001-5,000 employees
The query language is pretty straightforward and easy, and it is very powerful for building different searches and dashboards that will serve for later exploration of the same interests I have.
CSO at Altera
 

Room For Improvement

LogRhythm SIEM needs improved integration, user interface, automation, scalability, documentation, and compatibility with non-mainstream platforms and Linux.
Sumo Logic Security requires better dashboards, user experience, API integration, automation, pricing, scalability, stability, and improved threat intelligence.
I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
Cyber Security Engineer at Diyar United Company
There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments.
Security Engineer at Granicus Inc.
A more user-friendly user interface with drag-and-drop features, similar to key competitors like Splunk, would be beneficial.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
This can lead to alerts that are collections of disjointed signals that sometimes make no sense and lack real context; this simplistic approach makes it hard to find coherent stories during investigations.
CSO at Altera
I would also appreciate the AWS automation integrations to be more secure because currently, they are using access keys, which involves a user rather than roles, which is the security best practice recommended by AWS.
Senior Security Analyst at City Electric Supply Company
The correlation rules and log mapping are not as mature compared to other SIM tools like Splunk.
SOC Analyst at a computer software company with 1,001-5,000 employees
 

Setup Cost

LogRhythm SIEM is cost-effective for enterprises, offering transparent pricing and flexible licensing, yet incurs higher professional service fees.
Sumo Logic Security pricing is justified by its features, viewed as moderate compared to competitors like Splunk and QRadar.
The license cost is around $10 per MPS.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar.
Cyber Security Engineer at Diyar United Company
This makes it more cost-effective because other solutions often include a third element in their pricing.
Deputy Country Manager at PT Securite Asia Indonesia (ABP Securite)
 

Valuable Features

LogRhythm SIEM offers advanced threat detection, user-friendly interface, comprehensive log management, and automated alerts for enhanced security efficiency.
Sumo Logic Security offers user-friendly tools for efficient monitoring, real-time insights, and improved incident response through customizable features.
The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient.
Product Development - Security Solutions Manager at Aplikanusa Lintasarta
We have enough budget for cloud deployment, but we choose to keep it on-prem to ensure data privacy; cyberattacks are a concern, but data privacy is the foremost priority due to sensitive government information.
Cyber Security Engineer at Diyar United Company
This helps SOC analysts significantly as they can monitor all log sources through a dashboard, quickly identifying which sources haven't reported within their specified timeframes.
Security Engineer at Granicus Inc.
The features I find most useful in Sumo Logic Security are the ease of implementation and connectors; they have a very easy connection and many connectors to important systems, making it very easy to implement and fast to start running in production.
CSO at Altera
They are able to save time on fewer alerts because we are able to perform tuning on the logs to be able to only get relevant or security relevant incidents.
Senior Security Analyst at City Electric Supply Company
If we cannot find the data in other tools, like email security or NDR, we can fetch those logs in the Log Analytics platform of Sumo Logic.
SOC Analyst at a computer software company with 1,001-5,000 employees
 

Categories and Ranking

LogRhythm SIEM
Ranking in Log Management
13th
Ranking in Security Information and Event Management (SIEM)
9th
Average Rating
8.4
Reviews Sentiment
6.4
Number of Reviews
175
Ranking in other categories
No ranking in other categories
Sumo Logic Security
Ranking in Log Management
38th
Ranking in Security Information and Event Management (SIEM)
29th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
22
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (20th)
 

Mindshare comparison

As of January 2026, in the Security Information and Event Management (SIEM) category, the mindshare of LogRhythm SIEM is 2.6%, down from 3.3% compared to the previous year. The mindshare of Sumo Logic Security is 1.3%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
LogRhythm SIEM2.6%
Sumo Logic Security1.3%
Other96.1%
Security Information and Event Management (SIEM)
 

Featured Reviews

SV
Cyber Security Engineer at Diyar United Company
Provides strong detection capabilities but requires improvements in parsing and stability
I cannot think of any specific features that LogRhythm SIEM can improve upon since it supports a wide variety of major vendors. However, they need to improve their parsing techniques; the tool should understand various devices and present data in a human-readable format. For example, if a personal Android mobile needs to be integrated, LogRhythm SIEM should be able to parse that data effectively. They also need to improve their database of supported devices to cover smaller vendors alongside the major players, allowing for better global reach and usability. I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
MR
Senior Security Analyst at City Electric Supply Company
Security insights have enabled faster incident response and streamlined cross-team collaboration
To improve Sumo Logic Security, I would appreciate the tool being easier to use from a search perspective. For example, we have a few teams that want to use the tool itself, but they are not as savvy when it comes to creating searches from the core platform. I understand that Mobot has come out and is in the works, and it really does assist non-savvy users when it comes to querying the platform. As far as that is concerned, I wish that could be improved a bit more, but I do know that that is in the works. I would add that I wish for improved documentation. For example, we are using Sumo Playbooks and automation integrations along with that, but I have found that there has been a lack of documentation, very little to none at all when it comes to that. With regards to automation integrations as well, there are very few details included in them. I would also appreciate the AWS automation integrations to be more secure because currently, they are using access keys, which involves a user rather than roles, which is the security best practice recommended by AWS. I chose eight out of ten because to make it a nine or ten, I would lean heavily on the documentation. A lot of the times when we get around to configuring things such as playbooks or trying to understand playbooks, what I found was that documentation sometimes is not up to date or documentation is lacking. There are instances also where some security best practices are not being followed. So, if we are able to set up an integration that is not only secure, following security best practices, and has complete documentation, I believe it would alleviate the issue of having to go back and forth with support to check the documentation and things of that nature. My impression of the built-in threat intelligence feature in Sumo Logic Security is that it is comprehensive, but I would say that it could do a little bit better. For example, we have the TAXI feeds, which is STIX and TAXI integrated into the core platform, but the issue I am running into is that I am able to use that feed into a CSE alert; however, I am not able to see the contents of that feed. If I integrate CISA, which we do have integrated, I cannot see what IOCs are in that feed in the core platform, and I hope that is the case because, in order for us to better tune our alerts, we need to be able to see what is in the contents of that threat intelligence feed.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
880,844 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Government
9%
Manufacturing Company
8%
Financial Services Firm
7%
Manufacturing Company
13%
Computer Software Company
9%
Financial Services Firm
8%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise38
Large Enterprise83
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise4
Large Enterprise13
 

Questions from the Community

What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What needs improvement with LogRhythm NextGen SIEM?
One major area for improvement in LogRhythm SIEM is the lack of volume measurement capability in terms of storage. There is currently no way to determine how much data is being consumed in terms of...
What do you like most about LogRhythm SIEM?
I find LogRhythm's log management capabilities to be beneficial.
What do you like most about Sumo Logic Security?
Sumo Logic Security is a good solution for searching the logs and identifying the issues.
What is your experience regarding pricing and costs for Sumo Logic Security?
The pricing structure for Sumo Logic Security is based on two elements: data storage and the number of scans. This makes it more cost-effective because other solutions often include a third element...
What needs improvement with Sumo Logic Security?
One major improvement I would suggest for Sumo Logic Security is in its risk-based alerting system; while it initially sounds clever and modern, it works as a point-based system where an IP address...
 

Also Known As

LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
No data available
 

Overview

 

Sample Customers

Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Information Not Available
Find out what your peers are saying about LogRhythm SIEM vs. Sumo Logic Security and other solutions. Updated: December 2025.
880,844 professionals have used our research since 2012.